logo

CryptoWire with Decryption Key Included

ID: e2497a43-1b17-5d69-aec1-6c91a86ca3b2

STIX ID: report--e2497a43-1b17-5d69-aec1-6c91a86ca3b2

Feed Name: ASEC

Threat Score
70/100

Date Published: 2024-03-19

Date Updated: 2026-04-26

Author: kwonxx

...
...

AhnLab ASEC analyzed CryptoWire ransomware distributed via phishing and written in AutoIt; it persists by copying itself to "C\Program Files\Common Files" and registering scheduled tasks, enumerates local and network shares to encrypt files (appending .encrypted.[ext]), stores system info in domaincheck.txt, removes recovery options (empties recycle bin and deletes volume shadow copies), and sometimes embeds or exfiltrates the decryption key to a C2. The report provides behavioral detections, two MD5 hashes (a410d4535409a379fbda5bb5c32f6c9c, cd4a0b371cd7dc9dab6b442b0583550c) and a C2 URL (http://194.156.98.51/bot/log.php), and recommends caution with email attachments and keeping anti-malware updated.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.